Splunk Search

suppressing adjacent events with duplicate field values

Contributor

I have a log which often has redundant events, where "redundant" is defined as 2+ events, on subsequent lines, where each redundant event has the same value for a particular field (e.g. "ID").

How can I suppress the second and subsequent events so only the first event in a set shows up in my search results?

Tags (1)
0 Karma
1 Solution

Splunk Employee
Splunk Employee

You can pipe the events through | dedup consecutive=true fieldname

sourcetype=mydupeylog | dedup consecutive=true mydupeyfield

View solution in original post

Splunk Employee
Splunk Employee

You can pipe the events through | dedup consecutive=true fieldname

sourcetype=mydupeylog | dedup consecutive=true mydupeyfield

View solution in original post

Contributor

Cool! BTW, the docs for the dedup command are here: http://www.splunk.com/base/Documentation/latest/SearchReference/Dedup

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!